[2026 Latest] Preventing Residual Permissions with JML Automation: Mastering IDaaS Provisioning
With the average number of SaaS applications per company exceeding 30, account management associated with "JML (Joiner, Mover, Leaver)" is exhausting IT departments. In particular, failing to delete the IDs of former employees is a serious issue directly linked to the risk of information leakage. In our consulting work, we have seen many cases where "ghost accounts" resulting from manual operations are left unattended, serving as entry points for unauthorized access. This article explains specific measures for "IT Department DX"—balancing security and operational efficiency by automating JML processes using the provisioning features of IDaaS (such as Okta and Microsoft Entra ID)—based on our consulting insights.
Table of Contents (Click to open/close)
1. The Catastrophic Risks of Failing to Deactivate Former Employee IDs
In IT department support settings, we frequently encounter "ghost accounts" that remain able to log into specific SaaS platforms even months after an employee's departure. This is not merely a management oversight; it is a sign that manual operations have reached their physical limits.
Based on our actual support experience, since individual employees utilize a wide variety of tools, the rate of missed account deletions upon resignation tends to rise sharply once the number of tools exceeds ten. If these are privileged IDs (administrator accounts), it could easily lead to the unauthorized removal of confidential data or configuration changes, potentially undermining the very foundation of corporate trust.
2. How Automated Provisioning via SCIM Integration Works
The core of automation utilizing IDaaS (Identity as a Service) lies in the standard protocol known as SCIM (System for Cross-domain Identity Management). This allows user additions, changes, and deletions on the IDaaS side to be synchronized to each SaaS in real time.
For example, the moment a "resignation" status is finalized in the Human Resources Information System (HRIS), the IDaaS detects it and automatically de-provisions all integrated SaaS accounts in bulk. Common operational errors—such as "suspending an email account but forgetting Slack or core business systems"—can be fundamentally eliminated by implementing SCIM integration.
Furthermore, in the context of In-house EC site development and growth support, where there is frequent turnover of external partners and temporary staff, this ID provisioning mechanism contributes significantly to reducing operational costs and maintaining information governance.
3. Design Guidelines for Successful Real-World ID Lifecycle Management
When implementing automation, simply introducing tools is not enough. In our actual support engagements, we design "Lifecycle Management" with a focus on the following three points.
- Organizing HR data (SoR: System of Record): If the HR data that serves as the source for accounts is not accurate, automation will spread "incorrect settings" at high speed.
- Group-based access control (RBAC): Instead of granting permissions individually, link SaaS licenses and roles to "groups" within the IDaaS and automate permission changes during personnel transfers.
- Defining Exception Flows: Defining management flows in advance for users not registered in the HR system, such as contractors, is the key to preventing operations from becoming a mere formality.
By implementing such systems, the IT department will be freed from the routine task of account issuance, allowing them to devote more time to essential activities like IT strategy planning and strengthening security.
FAQ
- Q. How should SaaS that do not support SCIM be managed?
- A. For tools that do not support SCIM, we either build API integrations using IDaaS workflow features (such as Okta Workflows) or supplement automation via iPaaS. If integration is not feasible, we aim for "semi-automation," where IDaaS handles the automated generation of inventory lists, leaving only the final deletion task to be performed manually.
- Q. It seems like coordinating with the HR department for implementation would be difficult.
- A. In support settings, we make it easier to gain cooperation by clearly presenting "quantification of security risks" and "the impact of HR input errors on the system." It is important to promote this not just as an IT department issue, but as a company-wide project to strengthen compliance.
- Q. Can we prevent permissions from the previous department from remaining after a transfer?
- A. Yes, it is possible. By implementing thorough Role-Based Access Control (RBAC) and configuring settings to "revoke" permissions in real-time as group affiliations change, you can maintain the Principle of Least Privilege.
Automate your ID management and strengthen security
We propose strategies to organize complex SaaS account operations and minimize risk.
Talk to us for a free strategy consultationSummary
Automating JML (Joiner, Mover, Leaver) management is not just about efficiency; it is an essential security measure for modern cloud-native enterprises. By establishing synchronization with HR data centered on IDaaS provisioning (SCIM integration), you can physically prevent orphaned IDs and excessive permission granting caused by human error. To maximize the use of IT assets and transform into a proactive IT department, start by solidifying the foundation of your ID management.
Published: September 10, 2026 / By: Osamu Yasuda
Osamu Yasuda
Senior Managing Director & COO
Meets Consulting Inc.
Supported 100+ EC operations & logistics projects; specialist in operations and cost optimization
References
- [1] RFC 7643: SCIM Core Schema
- [2] Gartner: Magic Quadrant for Access Management 2024
- [3] NIST SP 800-207: Zero Trust Architecture

